Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps(snyk): update snyk snapshot #5239

Closed
wants to merge 1 commit into from
Closed

deps(snyk): update snyk snapshot #5239

wants to merge 1 commit into from

Conversation

snyk-bot
Copy link
Contributor

Why this PR?

a weekly update of the vulnerabilities snapshot for lighthouse

@patrickhulce
Copy link
Collaborator

hey @aviadatsnyk think could we get snapshots more similar to the one in #5080?

that makes it clear to see what's being added/removed and much smaller payload to keep in our bundle. since you're running your own script now it's somewhat out of our hands 😄

@aviadatsnyk
Copy link
Contributor

Of course!

@paulirish
Copy link
Member

@aviadatsnyk thanks!

fyi #5080 has now been merged. given that, we think it makes sense to keep the https://github.com/GoogleChrome/lighthouse/blob/master/lighthouse-core/scripts/update-vuln-snapshot.sh file in place (it was deleted in #5162)

that way your bot should be able to run this script, commit and PR like it has been. and we'll end up with the smaller cleaner files. sg?

I'll close the other PRs since this has all the context. (And I figure the bot will open a new one rather than update 5306 ;)

cheers.

@aviadatsnyk
Copy link
Contributor

totally agree. btw - the script was not deleted in #5162 (the PR wasn't merged) - so I think we're good.
I'll make future PRs submit the cleaned-up snapshot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants